@langchain/core

npm

Is @langchain/core safe to use?

Based on the latest brin safety scan, no vulnerabilities or threats were detected for @langchain/core v1.1.24. Trust score: 85/100. No known CVE vulnerabilities, no detected threat patterns, and no suspicious capabilities identified. This is an automated, point-in-time assessment.

Install (safety-checked)

@langchain/core Passed Security Checks

No security concerns detected

clean
CVEs

0

Threats

0

Install Scripts

0

No Concerns Detected

No security concerns detected in the latest brin assessment. This is an automated, point-in-time evaluation — security posture may change.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

@langchain/core Capabilities & Permissions

What @langchain/core can access when installed. Review these capabilities before using with AI agents like Cursor, Claude Code, or Codex.

Network Access

This package makes network requests.

ai.google.devapi.js.langchain.comdeveloper.mozilla.orgdocs.anthropic.comdocs.langchain.comexample.comgithub.comjs.langchain.comjson-schema.orgjsonpatch.com+8 more
Protocols: http, https

Filesystem Access

Writes to the filesystem.

.env (r).env (r).env (r).env (r).env (r).env (r).env (w).env (w)+7 more

Process Spawning

This package can spawn child processes.

Environment Variables

Accesses the following environment variables.

LANGSMITH_API_KEYMY_TRACER_ENABLEDUPSTASH_REDIS_REST_TOKENUPSTASH_REDIS_REST_URL

AGENTS.md for @langchain/core

Good instructions lead to good results. brin adds @langchain/core documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

@langchain/core Documentation & Source Code

For the full @langchain/core README, API documentation, and source code, visit the official package registry.

Frequently asked questions about @langchain/core safety

Weekly Downloads

2.7M

Version

1.1.24

License

MIT

Other Versions

Last Scanned

Feb 12, 2026

Trust Score

85/100·Legitimacy signals, not safety

Capabilities

Network

Connects to: ai.google.dev, api.js.langchain.com, developer.mozilla.org...

Filesystem

Writes files

Process

Spawns child processes

Environment

Accesses: LANGSMITH_API_KEY, MY_TRACER_ENABLED, UPSTASH_REDIS_REST_TOKEN...